🌊 The First Wave is open. Reserve your place for Rava general availability. Join now →
Browse
Discovery QuestionnaireTrustBermudaAIPricing
Trust Center

Your data deserves more than "best practices."

Defense in depth. Sovereign data residency. Transparent compliance. Everything an enterprise procurement team needs to do their job. In one place.

Security Architecture

Six layers of defense.

Security is not one feature. It is the way the platform is layered. Each layer protects against a different class of threat. A failure at one layer is contained by the next.

L1

Network Security

Azure App Service with TLS 1.2+, HSTS (365-day with preload), and CORS controls. All traffic encrypted in transit.

L2

Authentication

Multi-factor authentication, OAuth 2.0, SSO via Google Workspace and Microsoft Entra ID. SHA-256 hashed API keys with IP whitelisting.

L3

Authorization

Role-based access control with granular permissions on every entity. Query-level tenant isolation. Architecturally impossible cross-tenant access.

L4

Application Security

Four-layer input validation. Comprehensive security headers. OWASP Top 10 protections enforced at the framework level.

L5

Data Protection

AES-256 encryption at rest (Azure Transparent Data Encryption). TLS in transit. Azure Key Vault HSM for all secrets. BCrypt password hashing.

L6

Monitoring

Immutable audit logs. Security event alerting. Account lockout and rate limiting against credential stuffing.

Data Residency

Sovereign by default.

Customer data lives in Microsoft Azure's Canada region. And stays there. This is not a configurable preference; it is the deployment model.

Primary regionAzure Canada Central
Disaster recoveryAzure Canada East
Maren conversationsSame region as customer data
AI inferenceRegional Azure OpenAI + Anthropic with US fallback (no PII)
BackupsGeo-redundant within Canada
Data Protection

Encryption, isolation, retention.

Encryption at restAES-256 via Azure Transparent Data Encryption
Encryption in transitTLS 1.2+ with HSTS (365-day, preload)
Secret managementAzure Key Vault, HSM-backed
Password storageBCrypt one-way hashing. Never plaintext
Tenant isolationQuery-level. Architecturally impossible cross-tenant access
Audit retention7 years (meets Bermuda statutory requirements)
Data classificationRestricted, Confidential, Internal. Graded controls
Compliance

Frameworks we operate within.

Some frameworks are statutory in Bermuda. Some are inherited from Azure. Some are voluntary commitments we hold ourselves to.

PIPA

Bermuda Personal Information Protection Act. Data protection, 72-hour breach notification, consent management.

Bermuda Payroll Tax Act 1995

Full compliance with calculations, filings, classifications, and quarter-end submissions.

Employment Act 2000

Statutory leave entitlements, employment record retention (7-year), maternity/paternity provisions.

OWASP Top 10

Comprehensive protections against all OWASP Top 10 threats, enforced at the framework level.

SOC 2 Type II

In progress. Policy framework established; audit underway.

Azure inheritance

SOC 1/2/3, ISO 27001/27017/27018, FedRAMP, HIPAA. Microsoft Azure is our infrastructure provider.

Service Level

99.95% availability.

Backed by Azure App Service SLA. Graceful degradation means non-critical features (AI, analytics) degrade independently. Core payroll processing is always available.

Uptime SLA99.95% (Azure App Service)
Graceful degradationAI & analytics fail independently of payroll core
Maintenance windowsOff-hours, advance notice, zero-downtime where possible
Status pageComing with general availability
Incident Response

How we respond when things break.

Breach notificationWithin 72 hours (PIPA statutory)
Audit logsImmutable, real-time, queryable for 7 years
Security alertingAnomaly detection on auth, API, and data access
On-call24/7 engineering on-call with documented runbooks
Customer communicationDirect email + status page + post-incident report
Sub-processors

Who handles what. And where.

We are transparent about every vendor that touches your data. Any change is communicated in advance.

ServicePurposeLocationData scope
Microsoft AzureInfrastructure, database, app hosting, AI inferenceCanadaAll customer data
StripePayment processing (subscriptions)US / globalBilling data only
Azure OpenAIAI inference for Patty, Iris, MarenAI inference for Patty and IrisRegional (Canada preferred)Query payloads, no PII in summaries
AnthropicAI inference fallback & advanced reasoningUSQuery payloads, no PII in summaries
Documentation

Need a SOC 2 report? DPA? Security questionnaire?

Maren can route the request to the right person and turn it around within one business day.

Reach the security team directly. Most requests are turned around within one business day.

Email the security team

Have a specific security question?

Maren has been trained on this trust center. Ask her anything, and she will either answer or get you to someone who can.

Reach the security team. We will get back to you within one business day.

Talk to a human